Cotonti 1.0.0 及之前版本中, 函数存在开放重定向漏洞,该函数使用正则表达式验证重定向目标,但该正则表达式缺少字符串结束锚点。攻击者可以通过提供以站点域名开头的主机名来绕过重定向防护,从而通过评分插件或其他重定向调用方将用户重定向到攻击者控制的主机上。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93868 | 8.1 HIGH | Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
| CVE-2026-93872 | 7.5 HIGH | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter |
| CVE-2026-93871 | 5.4 MEDIUM | Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix |
| CVE-2026-93870 | 4.3 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler |
| CVE-2026-93873 | 4.3 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin |
No comments yet